<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width,initial-scale=1"><title>Largebin attack学习 | Icey's Blog</title><meta name="keywords" content="pwn,how2heap"><meta name="author" content="1c3y"><meta name="copyright" content="1c3y"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="Largebin分配流程概述 在一个chunk被插入unsorted bin后，当我们再去申请chunk时，会反向遍历unsorted bin的双向循环链表，如果没有匹配到合适的大小，则会将根据bin的大小，将其放置到对应的large bin或small bin 如果所需分配的chunk为largebin chunk，则会反向遍历largebin链表 找到第一个大于等于所需chunk大小的chun">
<meta property="og:type" content="article">
<meta property="og:title" content="Largebin attack学习">
<meta property="og:url" content="http://example.com/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/index.html">
<meta property="og:site_name" content="Icey&#39;s Blog">
<meta property="og:description" content="Largebin分配流程概述 在一个chunk被插入unsorted bin后，当我们再去申请chunk时，会反向遍历unsorted bin的双向循环链表，如果没有匹配到合适的大小，则会将根据bin的大小，将其放置到对应的large bin或small bin 如果所需分配的chunk为largebin chunk，则会反向遍历largebin链表 找到第一个大于等于所需chunk大小的chun">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://i.loli.net/2021/03/21/mLYCNvXPnutGfBI.jpg">
<meta property="article:published_time" content="2021-03-28T06:10:00.000Z">
<meta property="article:modified_time" content="2021-03-28T10:52:35.133Z">
<meta property="article:author" content="1c3y">
<meta property="article:tag" content="pwn">
<meta property="article:tag" content="how2heap">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://i.loli.net/2021/03/21/mLYCNvXPnutGfBI.jpg"><link rel="shortcut icon" href="/img/favicon.png"><link rel="canonical" href="http://example.com/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = { 
  root: '/',
  algolia: undefined,
  localSearch: undefined,
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: '复制成功',
    error: '复制错误',
    noSupport: '浏览器不支持'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '',
  date_suffix: {
    just: '刚刚',
    min: '分钟前',
    hour: '小时前',
    day: '天前',
    month: '个月前'
  },
  copyright: undefined,
  lightbox: 'fancybox',
  Snackbar: undefined,
  source: {
    jQuery: 'https://cdn.jsdelivr.net/npm/jquery@latest/dist/jquery.min.js',
    justifiedGallery: {
      js: 'https://cdn.jsdelivr.net/npm/justifiedGallery/dist/js/jquery.justifiedGallery.min.js',
      css: 'https://cdn.jsdelivr.net/npm/justifiedGallery/dist/css/justifiedGallery.min.css'
    },
    fancybox: {
      js: 'https://cdn.jsdelivr.net/npm/@fancyapps/fancybox@latest/dist/jquery.fancybox.min.js',
      css: 'https://cdn.jsdelivr.net/npm/@fancyapps/fancybox@latest/dist/jquery.fancybox.min.css'
    }
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isanchor: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = { 
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2021-03-28 18:52:35'
}</script><noscript><style type="text/css">
  #nav {
    opacity: 1
  }
  .justified-gallery img {
    opacity: 1
  }

  #recent-posts time,
  #post-meta time {
    display: inline !important
  }
</style></noscript><script>(win=>{
    win.saveToLocal = {
      set: function setWithExpiry(key, value, ttl) {
        if (ttl === 0) return
        const now = new Date()
        const expiryDay = ttl * 86400000
        const item = {
          value: value,
          expiry: now.getTime() + expiryDay,
        }
        localStorage.setItem(key, JSON.stringify(item))
      },

      get: function getWithExpiry(key) {
        const itemStr = localStorage.getItem(key)

        if (!itemStr) {
          return undefined
        }
        const item = JSON.parse(itemStr)
        const now = new Date()

        if (now.getTime() > item.expiry) {
          localStorage.removeItem(key)
          return undefined
        }
        return item.value
      }
    }
  
    win.getScript = url => new Promise((resolve, reject) => {
      const script = document.createElement('script')
      script.src = url
      script.async = true
      script.onerror = reject
      script.onload = script.onreadystatechange = function() {
        const loadState = this.readyState
        if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
        script.onload = script.onreadystatechange = null
        resolve()
      }
      document.head.appendChild(script)
    })
  
      win.activateDarkMode = function () {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = function () {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
          if (t === 'dark') activateDarkMode()
          else if (t === 'light') activateLightMode()
        
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    })(window)</script><meta name="generator" content="Hexo 5.4.0"><link rel="alternate" href="/atom.xml" title="Icey's Blog" type="application/atom+xml">
</head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="author-avatar"><img class="avatar-img" src="http://p.ananas.chaoxing.com/star3/origin/e79248a96a8b9a9f4c51e2e7beaabc5c.png" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="site-data"><div class="data-item is-center"><div class="data-item-link"><a href="/archives/"><div class="headline">文章</div><div class="length-num">7</div></a></div></div><div class="data-item is-center"><div class="data-item-link"><a href="/tags/"><div class="headline">标签</div><div class="length-num">3</div></a></div></div><div class="data-item is-center"><div class="data-item-link"><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div></div></div><hr/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div></div></div></div><div class="post" id="body-wrap"><header class="post-bg" id="page-header" style="background-image: url('https://i.loli.net/2021/03/21/mLYCNvXPnutGfBI.jpg')"><nav id="nav"><span id="blog_name"><a id="site-name" href="/">Icey's Blog</a></span><div id="menus"><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div></div><div id="toggle-menu"><a class="site-page"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">Largebin attack学习</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">发表于</span><time class="post-meta-date-created" datetime="2021-03-28T06:10:00.000Z" title="发表于 2021-03-28 14:10:00">2021-03-28</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">更新于</span><time class="post-meta-date-updated" datetime="2021-03-28T10:52:35.133Z" title="更新于 2021-03-28 18:52:35">2021-03-28</time></span><span class="post-meta-categories"><span class="post-meta-separator">|</span><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/%E4%BA%8C%E8%BF%9B%E5%88%B6%E6%BC%8F%E6%B4%9E/">二进制漏洞</a></span></div><div class="meta-secondline"><span class="post-meta-separator">|</span><span class="post-meta-pv-cv" id="" data-flag-title="Largebin attack学习"><i class="far fa-eye fa-fw post-meta-icon"></i><span class="post-meta-label">阅读量:</span><span id="busuanzi_value_page_pv"></span></span></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><h1 id="Largebin分配流程概述"><a href="#Largebin分配流程概述" class="headerlink" title="Largebin分配流程概述"></a>Largebin分配流程概述</h1><ul>
<li>在一个chunk被插入unsorted bin后，当我们再去申请chunk时，会反向遍历unsorted bin的双向循环链表，如果没有匹配到合适的大小，则会将根据bin的大小，将其放置到对应的large bin或small bin</li>
<li>如果所需分配的chunk为largebin chunk，则会反向遍历largebin链表</li>
<li>找到第一个大于等于所需chunk大小的chunk退出循环</li>
<li>将其切分后判断其剩余大小，如果大于MINSIZE，则构成新的chunk放入unsorted bin中</li>
<li>largebin链表中chunk按从大到小排列</li>
</ul>
<h1 id="源码分析"><a href="#源码分析" class="headerlink" title="源码分析"></a>源码分析</h1><h2 id="宏bin-at"><a href="#宏bin-at" class="headerlink" title="宏bin_at"></a>宏bin_at</h2><figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br></pre></td><td class="code"><pre><span class="line"><span class="comment">/* addressing -- note that bin_at(0) does not exist */</span></span><br><span class="line"><span class="meta">#<span class="meta-keyword">define</span> bin_at(m, i) \</span></span><br><span class="line">  (mbinptr) (((<span class="keyword">char</span> *) &amp;((m)-&gt;bins[((i) - <span class="number">1</span>) * <span class="number">2</span>]))			      \</span><br><span class="line">             - offsetof (struct malloc_chunk, fd))</span><br></pre></td></tr></table></figure>
<p>宏bin_at(m,i)通过bin index获得bin的链表头</p>
<h2 id="largebin取出操作"><a href="#largebin取出操作" class="headerlink" title="largebin取出操作"></a>largebin取出操作</h2><figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br><span class="line">9</span><br><span class="line">10</span><br><span class="line">11</span><br><span class="line">12</span><br><span class="line">13</span><br><span class="line">14</span><br><span class="line">15</span><br><span class="line">16</span><br><span class="line">17</span><br><span class="line">18</span><br><span class="line">19</span><br><span class="line">20</span><br><span class="line">21</span><br><span class="line">22</span><br><span class="line">23</span><br><span class="line">24</span><br><span class="line">25</span><br><span class="line">26</span><br><span class="line">27</span><br><span class="line">28</span><br><span class="line">29</span><br><span class="line">30</span><br><span class="line">31</span><br><span class="line">32</span><br><span class="line">33</span><br><span class="line">34</span><br><span class="line">35</span><br><span class="line">36</span><br><span class="line">37</span><br><span class="line">38</span><br><span class="line">39</span><br><span class="line">40</span><br><span class="line">41</span><br><span class="line">42</span><br><span class="line">43</span><br><span class="line">44</span><br><span class="line">45</span><br><span class="line">46</span><br><span class="line">47</span><br><span class="line">48</span><br><span class="line">49</span><br><span class="line">50</span><br><span class="line">51</span><br><span class="line">52</span><br><span class="line">53</span><br><span class="line">54</span><br><span class="line">55</span><br><span class="line">56</span><br><span class="line">57</span><br><span class="line">58</span><br><span class="line">59</span><br><span class="line">60</span><br><span class="line">61</span><br><span class="line">62</span><br><span class="line">63</span><br><span class="line">64</span><br><span class="line">65</span><br><span class="line">66</span><br><span class="line">67</span><br></pre></td><td class="code"><pre><span class="line"><span class="comment">/*</span></span><br><span class="line"><span class="comment">         If a large request, scan through the chunks of current bin in</span></span><br><span class="line"><span class="comment">         sorted order to find smallest that fits.  Use the skip list for this.</span></span><br><span class="line"><span class="comment">       */</span></span><br><span class="line"></span><br><span class="line">      <span class="keyword">if</span> (!in_smallbin_range (nb))</span><br><span class="line">        &#123;</span><br><span class="line">          bin = bin_at (av, idx);</span><br><span class="line"></span><br><span class="line">          <span class="comment">/* skip scan if empty or largest chunk is too small */</span></span><br><span class="line">          <span class="keyword">if</span> ((victim = first (bin)) != bin &amp;&amp;</span><br><span class="line">              (<span class="keyword">unsigned</span> <span class="keyword">long</span>) (victim-&gt;size) &gt;= (<span class="keyword">unsigned</span> <span class="keyword">long</span>) (nb))</span><br><span class="line">            &#123;<span class="comment">//如果large bin链表为空或者其中最大的chunk也无法满足要求，则不能从large bin中分配</span></span><br><span class="line">              victim = victim-&gt;bk_nextsize;</span><br><span class="line">              <span class="keyword">while</span> (((<span class="keyword">unsigned</span> <span class="keyword">long</span>) (size = chunksize (victim)) &lt;</span><br><span class="line">                      (<span class="keyword">unsigned</span> <span class="keyword">long</span>) (nb)))</span><br><span class="line">                victim = victim-&gt;bk_nextsize;<span class="comment">//此时victim的大小大于我们所需chunk，反向遍历链表，直到找到第一个大于等于所需chunk大小的chunk退出循环</span></span><br><span class="line"></span><br><span class="line">              <span class="comment">/* Avoid removing the first entry for a size so that the skip</span></span><br><span class="line"><span class="comment">                 list does not have to be rerouted.  */</span></span><br><span class="line">              <span class="comment">//如果选取的chunk victim不是链表中的最后一个chunk，并且与victim大小相同的chunk不止一个，则申请此时堆头chunk的下一个</span></span><br><span class="line">              <span class="keyword">if</span> (victim != last (bin) &amp;&amp; victim-&gt;size == victim-&gt;fd-&gt;size)</span><br><span class="line">                victim = victim-&gt;fd;</span><br><span class="line"></span><br><span class="line">              remainder_size = size - nb;<span class="comment">//将victim进行切割</span></span><br><span class="line">              unlink (av, victim, bck, fwd);<span class="comment">//调用unlink()宏将victim从large bin中取出</span></span><br><span class="line"></span><br><span class="line">              <span class="comment">/* Exhaust */</span></span><br><span class="line">              <span class="keyword">if</span> (remainder_size &lt; MINSIZE)</span><br><span class="line">                &#123;<span class="comment">//如果victim切分后剩余大小小于MINSIZE，则将整个victim分配给应用层，这种情况下，实际分配的chunk比所需的chunk大一些</span></span><br><span class="line">                  set_inuse_bit_at_offset (victim, size);</span><br><span class="line">                  <span class="keyword">if</span> (av != &amp;main_arena)</span><br><span class="line">                    victim-&gt;size |= NON_MAIN_ARENA;</span><br><span class="line">                &#125;</span><br><span class="line">              <span class="comment">/* Split */</span></span><br><span class="line">              <span class="keyword">else</span></span><br><span class="line">                &#123;<span class="comment">//如果剩余空间还可以构成chunk，则将其放入unsorted bin</span></span><br><span class="line">                  remainder = chunk_at_offset (victim, nb);</span><br><span class="line">                  <span class="comment">/* We cannot assume the unsorted list is empty and therefore</span></span><br><span class="line"><span class="comment">                     have to perform a complete insert here.  */</span></span><br><span class="line">                  bck = unsorted_chunks (av);</span><br><span class="line">                  fwd = bck-&gt;fd; <span class="comment">//fwd是unsorted bin第一个chunk</span></span><br><span class="line">	  <span class="keyword">if</span> (__glibc_unlikely (fwd-&gt;bk != bck))</span><br><span class="line">                    &#123;</span><br><span class="line">                      errstr = <span class="string">&quot;malloc(): corrupted unsorted chunks&quot;</span>;</span><br><span class="line">                      <span class="keyword">goto</span> errout;</span><br><span class="line">                    &#125;</span><br><span class="line">                  remainder-&gt;bk = bck;</span><br><span class="line">                  remainder-&gt;fd = fwd;</span><br><span class="line">                  bck-&gt;fd = remainder;</span><br><span class="line">                  fwd-&gt;bk = remainder;</span><br><span class="line">                  <span class="keyword">if</span> (!in_smallbin_range (remainder_size))</span><br><span class="line">                    &#123;</span><br><span class="line">                      remainder-&gt;fd_nextsize = <span class="literal">NULL</span>;</span><br><span class="line">                      remainder-&gt;bk_nextsize = <span class="literal">NULL</span>;</span><br><span class="line">                    &#125;</span><br><span class="line">                  set_head (victim, nb | PREV_INUSE |</span><br><span class="line">                            (av != &amp;main_arena ? NON_MAIN_ARENA : <span class="number">0</span>));</span><br><span class="line">                  set_head (remainder, remainder_size | PREV_INUSE);</span><br><span class="line">                  set_foot (remainder, remainder_size);</span><br><span class="line">                &#125;</span><br><span class="line">              check_malloced_chunk (av, victim, nb);</span><br><span class="line">              <span class="keyword">void</span> *p = chunk2mem (victim);</span><br><span class="line">              alloc_perturb (p, bytes);</span><br><span class="line">              <span class="keyword">return</span> p;</span><br><span class="line">            &#125;</span><br><span class="line">        &#125;</span><br></pre></td></tr></table></figure>

<h2 id="largebin插入操作"><a href="#largebin插入操作" class="headerlink" title="largebin插入操作"></a>largebin插入操作</h2><figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br><span class="line">9</span><br><span class="line">10</span><br><span class="line">11</span><br><span class="line">12</span><br><span class="line">13</span><br><span class="line">14</span><br><span class="line">15</span><br><span class="line">16</span><br><span class="line">17</span><br><span class="line">18</span><br><span class="line">19</span><br><span class="line">20</span><br><span class="line">21</span><br><span class="line">22</span><br><span class="line">23</span><br><span class="line">24</span><br><span class="line">25</span><br><span class="line">26</span><br><span class="line">27</span><br><span class="line">28</span><br><span class="line">29</span><br><span class="line">30</span><br><span class="line">31</span><br><span class="line">32</span><br><span class="line">33</span><br><span class="line">34</span><br><span class="line">35</span><br><span class="line">36</span><br><span class="line">37</span><br><span class="line">38</span><br><span class="line">39</span><br><span class="line">40</span><br><span class="line">41</span><br><span class="line">42</span><br><span class="line">43</span><br><span class="line">44</span><br><span class="line">45</span><br><span class="line">46</span><br><span class="line">47</span><br><span class="line">48</span><br><span class="line">49</span><br><span class="line">50</span><br><span class="line">51</span><br><span class="line">52</span><br><span class="line">53</span><br><span class="line">54</span><br><span class="line">55</span><br><span class="line">56</span><br><span class="line">57</span><br><span class="line">58</span><br><span class="line">59</span><br><span class="line">60</span><br><span class="line">61</span><br><span class="line">62</span><br><span class="line">63</span><br><span class="line">64</span><br><span class="line">65</span><br><span class="line">66</span><br><span class="line">67</span><br><span class="line">68</span><br></pre></td><td class="code"><pre><span class="line"><span class="comment">/* place chunk in bin */</span></span><br><span class="line"></span><br><span class="line">          <span class="keyword">if</span> (in_smallbin_range (size))</span><br><span class="line">            &#123;</span><br><span class="line">              victim_index = smallbin_index (size);</span><br><span class="line">              bck = bin_at (av, victim_index);</span><br><span class="line">              fwd = bck-&gt;fd;</span><br><span class="line">            &#125;</span><br><span class="line">          <span class="keyword">else</span></span><br><span class="line">            &#123;<span class="comment">//所需chunk不属于small bins，则一定属于large bins</span></span><br><span class="line">             <span class="comment">//根据chunk的大小获得对应large bin的index</span></span><br><span class="line">              victim_index = largebin_index (size);</span><br><span class="line">              bck = bin_at (av, victim_index);<span class="comment">//bck为large bin的链表头</span></span><br><span class="line">              fwd = bck-&gt;fd;<span class="comment">//链表首元结点</span></span><br><span class="line"></span><br><span class="line">              <span class="comment">/* maintain large bins in sorted order */</span></span><br><span class="line">              <span class="keyword">if</span> (fwd != bck)</span><br><span class="line">                &#123;<span class="comment">//如果fwd不等于bck，则意味着large bin中有空闲chunk存在</span></span><br><span class="line">                  <span class="comment">/* Or with inuse bit to speed comparisons */</span></span><br><span class="line">                  size |= PREV_INUSE;</span><br><span class="line">                  <span class="comment">/* if smaller than smallest, bypass loop below */</span></span><br><span class="line">                  assert ((bck-&gt;bk-&gt;size &amp; NON_MAIN_ARENA) == <span class="number">0</span>);<span class="comment">//是否在主线程</span></span><br><span class="line">                  <span class="keyword">if</span> ((<span class="keyword">unsigned</span> <span class="keyword">long</span>) (size) &lt; (<span class="keyword">unsigned</span> <span class="keyword">long</span>) (bck-&gt;bk-&gt;size))</span><br><span class="line">                    &#123;<span class="comment">//如果所需chunk比large bin的最后一个chunk大小还小，那么当前chunk就插入到large bin的链表的最后</span></span><br><span class="line">                      fwd = bck; <span class="comment">//此时fwd为链表表头</span></span><br><span class="line">                      bck = bck-&gt;bk; <span class="comment">//bck置为链表的最后一个chunk</span></span><br><span class="line"></span><br><span class="line">                      victim-&gt;fd_nextsize = fwd-&gt;fd;<span class="comment">//victim要插入到链表最后，那么比它小的就是链表的首元结点</span></span><br><span class="line">                      victim-&gt;bk_nextsize = fwd-&gt;fd-&gt;bk_nextsize;<span class="comment">//比它大的就是最小的那一个（双向链表的插入操作）</span></span><br><span class="line">                      fwd-&gt;fd-&gt;bk_nextsize = victim-&gt;bk_nextsize-&gt;fd_nextsize = victim;<span class="comment">//完成插入操作，画个图就懂了</span></span><br><span class="line">                    &#125;</span><br><span class="line">                  <span class="keyword">else</span></span><br><span class="line">                    &#123;<span class="comment">//正向遍历链表，直到找到第一个chunk大小小于等于当前chunk大小的chunk退出循环</span></span><br><span class="line">                      assert ((fwd-&gt;size &amp; NON_MAIN_ARENA) == <span class="number">0</span>);</span><br><span class="line">                      <span class="keyword">while</span> ((<span class="keyword">unsigned</span> <span class="keyword">long</span>) size &lt; fwd-&gt;size)</span><br><span class="line">                        &#123;</span><br><span class="line">                          fwd = fwd-&gt;fd_nextsize;</span><br><span class="line">                          assert ((fwd-&gt;size &amp; NON_MAIN_ARENA) == <span class="number">0</span>);</span><br><span class="line">                        &#125;</span><br><span class="line"></span><br><span class="line">                      <span class="keyword">if</span> ((<span class="keyword">unsigned</span> <span class="keyword">long</span>) size == (<span class="keyword">unsigned</span> <span class="keyword">long</span>) fwd-&gt;size)</span><br><span class="line">                        <span class="comment">/* Always insert in the second position.  */</span></span><br><span class="line">                        <span class="comment">//如果找到了大小相同的chunk</span></span><br><span class="line">                        fwd = fwd-&gt;fd;</span><br><span class="line">                      <span class="keyword">else</span></span><br><span class="line">                        &#123;<span class="comment">//双向链表插入</span></span><br><span class="line">                          victim-&gt;fd_nextsize = fwd;</span><br><span class="line">                          victim-&gt;bk_nextsize = fwd-&gt;bk_nextsize;</span><br><span class="line">                          fwd-&gt;bk_nextsize = victim;</span><br><span class="line">                          victim-&gt;bk_nextsize-&gt;fd_nextsize = victim;</span><br><span class="line">                        &#125;</span><br><span class="line">                      bck = fwd-&gt;bk;</span><br><span class="line">                    &#125;</span><br><span class="line">                &#125;</span><br><span class="line">              <span class="keyword">else</span></span><br><span class="line">                victim-&gt;fd_nextsize = victim-&gt;bk_nextsize = victim;<span class="comment">//唯一的chunk，也做成循环链表</span></span><br><span class="line">            &#125;</span><br><span class="line"></span><br><span class="line">          mark_bin (av, victim_index);</span><br><span class="line">          victim-&gt;bk = bck;</span><br><span class="line">          victim-&gt;fd = fwd;</span><br><span class="line">          fwd-&gt;bk = victim;</span><br><span class="line">          bck-&gt;fd = victim;</span><br><span class="line"></span><br><span class="line"><span class="meta">#<span class="meta-keyword">define</span> MAX_ITERS       10000</span></span><br><span class="line">          <span class="keyword">if</span> (++iters &gt;= MAX_ITERS)</span><br><span class="line">            <span class="keyword">break</span>;</span><br><span class="line">        &#125;</span><br></pre></td></tr></table></figure>

<h1 id="how2heap源码调试"><a href="#how2heap源码调试" class="headerlink" title="how2heap源码调试"></a>how2heap源码调试</h1><p>先申请三个堆块和fastbin，防止free的时候与top chunk合并</p>
<p><img src="https://i.loli.net/2021/03/28/XPT4i62LBxmqjad.png"></p>
<p>接着释放p1和p2</p>
<p><img src="https://i.loli.net/2021/03/28/G1sFljKpOLEgXJW.png"></p>
<p>然后会申请一个0x90大小的chunk，根据上文源码分析可知，此时会将unsorted bin里的p1放入small bin，将p2放入large bin，由于我们申请的大小为0x90，会到small bin里找，将p1进行切割以满足0x90的要求，并剩余的大小（0x330-0xa0）放入unsorted bin里</p>
<p><img src="https://i.loli.net/2021/03/28/AD3xhykYF9Bwn1p.png"><br><img src="https://i.loli.net/2021/03/28/RXhSLcxeN39rf7D.png"></p>
<p>接下来修改p2:</p>
<table>
<thead>
<tr>
<th align="center">previous chunk size</th>
<th align="center">size=0x3f1</th>
</tr>
</thead>
<tbody><tr>
<td align="center"><strong>fd=0</strong></td>
<td align="center"><strong>bk=addr1</strong></td>
</tr>
<tr>
<td align="center"><strong>fd_nextsize=0</strong></td>
<td align="center"><strong>bk_nextsize=addr2</strong></td>
</tr>
</tbody></table>
<p>修改后：</p>
<p><img src="https://i.loli.net/2021/03/28/wzx1nrUfmpOvLW6.png"></p>
<p>此时再申请0x90的chunk，将size=0x291的chunk放入small bin，将size=0x411的chunk放入large bin<br>由于之前p2的大小被修改为0x3f1&lt;0x411，所以会执行下面的操作：</p>
<figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br></pre></td><td class="code"><pre><span class="line"><span class="keyword">else</span></span><br><span class="line">    &#123;<span class="comment">//双向链表插入</span></span><br><span class="line">        victim-&gt;fd_nextsize = fwd;</span><br><span class="line">        victim-&gt;bk_nextsize = fwd-&gt;bk_nextsize;</span><br><span class="line">        fwd-&gt;bk_nextsize = victim;</span><br><span class="line">        victim-&gt;bk_nextsize-&gt;fd_nextsize = victim;</span><br><span class="line">    &#125;</span><br><span class="line">bck = fwd-&gt;bk;                 &#125;</span><br></pre></td></tr></table></figure>

<p>即</p>
<figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br></pre></td><td class="code"><pre><span class="line">victim-&gt;bk_nextsize = fwd-&gt;bk_nextsize;</span><br><span class="line">victim-&gt;bk_nextsize-&gt;fd_nextsize = victim;</span><br><span class="line"><span class="comment">//--&gt;</span></span><br><span class="line">addr2-&gt;fd_nextsize = victim;</span><br><span class="line">*(addr2+<span class="number">4</span>) = victim;</span><br></pre></td></tr></table></figure>

<p>还有另一个利用：</p>
<figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br></pre></td><td class="code"><pre><span class="line">mark_bin (av, victim_index);</span><br><span class="line">victim-&gt;bk = bck;</span><br><span class="line">victim-&gt;fd = fwd;</span><br><span class="line">fwd-&gt;bk = victim;</span><br><span class="line">bck-&gt;fd = victim;</span><br></pre></td></tr></table></figure>

<p>即</p>
<figure class="highlight c"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br></pre></td><td class="code"><pre><span class="line">victim-&gt;bk = addr1 = bck</span><br><span class="line">bck-&gt;fd = victim</span><br><span class="line">addr1-&gt;fd = victim</span><br><span class="line"><span class="comment">//--&gt;</span></span><br><span class="line">*(addr1+<span class="number">2</span>) = victim</span><br></pre></td></tr></table></figure>
<h1 id="例题练习"><a href="#例题练习" class="headerlink" title="例题练习"></a>例题练习</h1><p>有空再做</p>
<h1 id="largebin-attack的利用方法"><a href="#largebin-attack的利用方法" class="headerlink" title="largebin attack的利用方法"></a>largebin attack的利用方法</h1><ul>
<li>可以修改一个 large bin chunk 的 data</li>
<li>从 unsorted bin 中来的 large bin chunk 要紧跟在被构造过的 chunk 的后面</li>
</ul>
</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta">文章作者: </span><span class="post-copyright-info"><a href="mailto:undefined">1c3y</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta">文章链接: </span><span class="post-copyright-info"><a href="http://example.com/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/">http://example.com/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta">版权声明: </span><span class="post-copyright-info">本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/" target="_blank">CC BY-NC-SA 4.0</a> 许可协议。转载请注明来自 <a href="http://example.com" target="_blank">Icey's Blog</a>！</span></div></div><div class="tag_share"><div class="post-meta__tag-list"><a class="post-meta__tags" href="/tags/pwn/">pwn</a><a class="post-meta__tags" href="/tags/how2heap/">how2heap</a></div><div class="post_share"><div class="social-share" data-image="https://i.loli.net/2021/03/21/mLYCNvXPnutGfBI.jpg" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/social-share.js/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/social-share.js/dist/js/social-share.min.js" defer></script></div></div><nav class="pagination-post" id="pagination"><div class="next-post pull-full"><a href="/2021/03/22/BUUOJ%E5%88%B7%E9%A2%98%E8%AE%B0%E5%BD%95%E8%A1%A5%E6%A1%A31/"><img class="next-cover" src="https://i.loli.net/2021/03/21/2lRt7MpyxaGS8u4.jpg" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">下一篇</div><div class="next_info">BUUOJ刷题记录补档-1</div></div></a></div></nav><div class="relatedPosts"><div class="headline"><i class="fas fa-thumbs-up fa-fw"></i><span> 相关推荐</span></div><div class="relatedPosts-list"><div><a href="/2021/03/20/House of Spirit学习/" title="House of Spirit学习"><img class="cover" src="https://i.loli.net/2021/03/21/pB2PXv3LnAsYNMO.jpg" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2021-03-20</div><div class="title">House of Spirit学习</div></div></a></div><div><a href="/2021/02/07/ciscn_2019_es_2/" title="ciscn_2019_es_2"><img class="cover" src="https://i.loli.net/2021/03/21/y2xBT68QnRUC3O9.jpg" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2021-02-07</div><div class="title">ciscn_2019_es_2</div></div></a></div><div><a href="/2021/03/14/[V&N2020 公开赛]simpleHeap/" title="V&N2020 公开赛 simpleHeap"><img class="cover" src="https://i.loli.net/2021/03/21/1WR5tiS8lsc9wXb.jpg" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2021-03-14</div><div class="title">V&N2020 公开赛 simpleHeap</div></div></a></div><div><a href="/2021/01/25/get_started_3dsctf_2016/" title="get_started_3dsctf_2016"><img class="cover" src="https://i.loli.net/2021/03/21/FpLYGZ5oVaXI4s9.jpg" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2021-01-25</div><div class="title">get_started_3dsctf_2016</div></div></a></div><div><a href="/2021/03/22/BUUOJ刷题记录补档1/" title="BUUOJ刷题记录补档-1"><img class="cover" src="https://i.loli.net/2021/03/21/2lRt7MpyxaGS8u4.jpg" alt="cover"><div class="content is-center"><div class="date"><i class="far fa-calendar-alt fa-fw"></i> 2021-03-22</div><div class="title">BUUOJ刷题记录补档-1</div></div></a></div></div></div></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="card-info-avatar is-center"><img class="avatar-img" src="http://p.ananas.chaoxing.com/star3/origin/e79248a96a8b9a9f4c51e2e7beaabc5c.png" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/><div class="author-info__name">1c3y</div><div class="author-info__description">Welcome</div></div><div class="card-info-data"><div class="card-info-data-item is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">7</div></a></div><div class="card-info-data-item is-center"><a href="/tags/"><div class="headline">标签</div><div class="length-num">3</div></a></div><div class="card-info-data-item is-center"><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div></div><a class="button--animated" id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/xxxxxx"><i class="fab fa-github"></i><span>Follow Me</span></a></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn card-announcement-animation"></i><span>公告</span></div><div class="announcement_content">This is my Blog</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>目录</span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-1"><a class="toc-link" href="#Largebin%E5%88%86%E9%85%8D%E6%B5%81%E7%A8%8B%E6%A6%82%E8%BF%B0"><span class="toc-number">1.</span> <span class="toc-text">Largebin分配流程概述</span></a></li><li class="toc-item toc-level-1"><a class="toc-link" href="#%E6%BA%90%E7%A0%81%E5%88%86%E6%9E%90"><span class="toc-number">2.</span> <span class="toc-text">源码分析</span></a><ol class="toc-child"><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%AE%8Fbin-at"><span class="toc-number">2.1.</span> <span class="toc-text">宏bin_at</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#largebin%E5%8F%96%E5%87%BA%E6%93%8D%E4%BD%9C"><span class="toc-number">2.2.</span> <span class="toc-text">largebin取出操作</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#largebin%E6%8F%92%E5%85%A5%E6%93%8D%E4%BD%9C"><span class="toc-number">2.3.</span> <span class="toc-text">largebin插入操作</span></a></li></ol></li><li class="toc-item toc-level-1"><a class="toc-link" href="#how2heap%E6%BA%90%E7%A0%81%E8%B0%83%E8%AF%95"><span class="toc-number">3.</span> <span class="toc-text">how2heap源码调试</span></a></li><li class="toc-item toc-level-1"><a class="toc-link" href="#%E4%BE%8B%E9%A2%98%E7%BB%83%E4%B9%A0"><span class="toc-number">4.</span> <span class="toc-text">例题练习</span></a></li><li class="toc-item toc-level-1"><a class="toc-link" href="#largebin-attack%E7%9A%84%E5%88%A9%E7%94%A8%E6%96%B9%E6%B3%95"><span class="toc-number">5.</span> <span class="toc-text">largebin attack的利用方法</span></a></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/" title="Largebin attack学习"><img src="https://i.loli.net/2021/03/21/mLYCNvXPnutGfBI.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Largebin attack学习"/></a><div class="content"><a class="title" href="/2021/03/28/Largebin%20attack%E5%AD%A6%E4%B9%A0/" title="Largebin attack学习">Largebin attack学习</a><time datetime="2021-03-28T06:10:00.000Z" title="发表于 2021-03-28 14:10:00">2021-03-28</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2021/03/22/BUUOJ%E5%88%B7%E9%A2%98%E8%AE%B0%E5%BD%95%E8%A1%A5%E6%A1%A31/" title="BUUOJ刷题记录补档-1"><img src="https://i.loli.net/2021/03/21/2lRt7MpyxaGS8u4.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="BUUOJ刷题记录补档-1"/></a><div class="content"><a class="title" href="/2021/03/22/BUUOJ%E5%88%B7%E9%A2%98%E8%AE%B0%E5%BD%95%E8%A1%A5%E6%A1%A31/" title="BUUOJ刷题记录补档-1">BUUOJ刷题记录补档-1</a><time datetime="2021-03-22T13:19:00.000Z" title="发表于 2021-03-22 21:19:00">2021-03-22</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2021/03/20/House%20of%20Spirit%E5%AD%A6%E4%B9%A0/" title="House of Spirit学习"><img src="https://i.loli.net/2021/03/21/pB2PXv3LnAsYNMO.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="House of Spirit学习"/></a><div class="content"><a class="title" href="/2021/03/20/House%20of%20Spirit%E5%AD%A6%E4%B9%A0/" title="House of Spirit学习">House of Spirit学习</a><time datetime="2021-03-20T06:49:00.000Z" title="发表于 2021-03-20 14:49:00">2021-03-20</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2021/03/14/%5BV&amp;N2020%20%E5%85%AC%E5%BC%80%E8%B5%9B%5DsimpleHeap/" title="V&amp;N2020 公开赛 simpleHeap"><img src="https://i.loli.net/2021/03/21/1WR5tiS8lsc9wXb.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="V&amp;N2020 公开赛 simpleHeap"/></a><div class="content"><a class="title" href="/2021/03/14/%5BV&amp;N2020%20%E5%85%AC%E5%BC%80%E8%B5%9B%5DsimpleHeap/" title="V&amp;N2020 公开赛 simpleHeap">V&amp;N2020 公开赛 simpleHeap</a><time datetime="2021-03-14T01:27:00.000Z" title="发表于 2021-03-14 09:27:00">2021-03-14</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2021/02/07/ciscn_2019_es_2/" title="ciscn_2019_es_2"><img src="https://i.loli.net/2021/03/21/y2xBT68QnRUC3O9.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="ciscn_2019_es_2"/></a><div class="content"><a class="title" href="/2021/02/07/ciscn_2019_es_2/" title="ciscn_2019_es_2">ciscn_2019_es_2</a><time datetime="2021-02-07T06:59:00.000Z" title="发表于 2021-02-07 14:59:00">2021-02-07</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2020 - 2021 By 1c3y</div><div class="framework-info"><span>框架 </span><a target="_blank" rel="noopener" href="https://hexo.io">Hexo</a><span class="footer-separator">|</span><span>主题 </span><a target="_blank" rel="noopener" href="https://github.com/jerryc127/hexo-theme-butterfly">Butterfly</a></div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="阅读模式"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="目录"><i class="fas fa-list-ul"></i></button><button id="go-up" type="button" title="回到顶部"><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><div class="js-pjax"></div><script defer="defer" id="fluttering_ribbon" mobile="true" src="https://cdn.jsdelivr.net/npm/butterfly-extsrc@1/dist/canvas-fluttering-ribbon.min.js"></script><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>